Dynamic Management of Network Flows
Abstract
A plurality of flow network elements monitors network flows at the subscriber level for a plurality of subscribers. The flow network elements export flow records to a collector, which organizes the flow records. A policy client correlates the flow records and determines whether any network flows are violating a flow policy definition. If a flow policy definition is violated, the policy client transmits a policy action to a policy server which indicates what action to take for a given violating flow. The policy server assigns a flow policy for the subscriber corresponding with the violating flow. The assigned flow policy is then transmitted to the flow network element having that violating flow, and that flow network element installs the flow policy.
Claims
exact text as granted — not AI-modified1 . A method performed by a flow network element in a network flow management system, the method comprising the flow network element performing the steps of:
monitoring network flows at a subscriber-level for a plurality of subscribers; exporting flow records associated with the plurality of subscribers, wherein each flow record includes an identification of which one of the plurality of subscribers the flow record belongs; receiving one or more flow policies that were assigned by applying the exported flow records against a plurality of policy rule definitions, wherein each received flow policy identifies an action to take on network parameters associated with one of the plurality of subscribers as a result of violating one or more policy rules; and applying the one or more flow policies, wherein each applied flow policy modifies at least some of the network parameters associated with one of the plurality of subscribers.
2 . The method of claim 1 , wherein the network parameters include connection attributes including one or more of bandwidth values, access control lists, and policing values.
3 . The method of claim 1 , wherein at least two flow policies are received and applied, and wherein at least one of the applied flow policies affects all network traffic of a first subscriber, and wherein at least one other of the applied flow policies affects only a single network flow of a second subscriber.
4 . The method of claim 1 , wherein at least one of the plurality of subscribers is a mobile subscriber and at least one of the plurality of subscribers is a fixed subscriber.
5 . The method of claim 1 , further comprising:
for each of the plurality of subscribers, receiving an observation profile associated with the subscriber from an authentication, authorization, and accounting (AAA) server, the observation profile indicating network flow monitoring parameters for the subscriber; programming a plurality of subscriber-level flow observation points according to the received observation profiles.
6 . The method of claim 5 , wherein the observation profiles are received as part of an authentication or re-authentication request from the subscribers, and wherein the observation profiles are associated with subscriber records associated with the subscribers.
7 . The method of claim 5 , wherein the network flow monitoring parameters of each observation profile indicate which ones of a plurality of network flows associated with the subscriber to monitor.Join the waitlist — get patent alerts
Track US2013021906A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.